Skip to content

docs(skills): regenerate the provider endpoints reference - #15454

Closed
HouMinXi wants to merge 3 commits into
diegosouzapw:release/v3.8.52from
HouMinXi:fix/release-v3.8.52-basereds
Closed

HouMinXi wants to merge 3 commits into
diegosouzapw:release/v3.8.52from
HouMinXi:fix/release-v3.8.52-basereds

Conversation

@HouMinXi

@HouMinXi HouMinXi commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • The agent-skills generator was behind the code on release/v3.8.52. Three provider routes (/api/providers/validate, /api/providers/bulk, /api/providers/import) carry a loopback-only note from the credential-validation spawn audit, but the generated skills/omni-providers/references/endpoints.md never picked it up.
  • Regenerated that reference. check:agent-skills-sync now exits clean, which clears the "Merge integrity (changelog + generated skills)" failure that every PR into this release branch inherits.
  • next moves from 16.3.5 to 16.3.8. The lint job's audit:deps step fails on critical advisories. The critical one on this branch is next >=16.2.0 <16.3.6 (remote code execution in next/og ImageResponse). 16.3.8 is the fixed release on the same 16.3 line. High advisories such as @grpc/grpc-js and axios stay warnings in that script and are not what fails the job.

Related Issues

Validation

  • Change type: docs (generated skill reference) and deps (next patch)
  • node --import tsx/esm scripts/skills/generate-agent-skills.mjs exits 0 after the change (dry-run reports nothing left to generate)
  • npm audit --audit-level=critical reports no critical advisories after installing next@16.3.8
  • npm run audit:deps exits 0
  • npm run typecheck:core passes
  • fumadocs-core@16.15.4 peers on next@16.x.x
  • Reconciled with release/v3.8.52 @ 23a1148486

Tests Added Or Updated

  • None. The change is the output of the repository's own skill generator, and the generator's dry-run is the check.

Coverage Notes

  • Not applicable. No production code changes.

Reviewer Notes

  • The six added lines in the endpoints reference are the generator's own output, not hand-written. The same command produces them on a clean release/v3.8.52 checkout.
  • The lockfile change is only next 16.3.5 to 16.3.8 plus the @next/env and @next/swc-* packages that release ships. No other dependency moved.
  • This repo does not import next/og. The advisory is in the dependency itself.
  • This does not touch the six HARD failures in 🔴 Release branch not green: release/v3.8.52 #15306 (suite timeouts, the vitest audit checkpoint, the package-artifact timeout, the ai-attribution git log error). Those are separate.

The agent-skills generator was behind the code. Three provider routes
gained a loopback-only note in the audit for the credential-validation
spawn, and the generated endpoints reference never picked it up, so the
skills sync check failed on the release branch.

Signed-off-by: Minxi Hou <houminxi@gmail.com>
@HouMinXi
HouMinXi requested a review from diegosouzapw as a code owner October 3, 2026 13:55
audit:deps fails the lint job on a critical advisory, not on the high
ones. Those high findings are warnings. The critical one is next 16.3.5,
inside >=16.2.0 <16.3.6, the ImageResponse RCE in next/og. 16.3.8 is the
fixed release on the same 16.3 line. fumadocs-core accepts next 16.x.
Nothing in this repo imports next/og. The lockfile moves only next and
the @next packages it ships.

Signed-off-by: Minxi Hou <houminxi@gmail.com>
@diegosouzapw

Copy link
Copy Markdown
Owner

Closing as superseded by #15652.

skills/omni-providers/references/endpoints.md on this head is the same blob as release/v3.8.52 (9365c48f1ab86b5d8cac5431fd866779fb400a8a). Nothing in this diff is left to land.

Thanks @HouMinXi.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants